Advertisement
DhiaLite

Predicted next Nuclear IPs - Feb 22, 2014

Feb 22nd, 2014
358
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.90 KB | None | 0 0
  1. Sat, Feb 22 2014
  2. #DhiaLite - Predicted next IPs to host NuclearPack EK subdomains
  3.  
  4. Nuclear started today on 198.50.143.65
  5.  
  6. https://twitter.com/jedisct1/status/437298370973937664
  7. https://twitter.com/DhiaLite/status/437315196076314624
  8.  
  9. 198.50.143.65 is part of the range 198.50.143.64 - 198.50.143.79 sub-allocated at OVH
  10.  
  11. Although, IPs in this range have been used to host older content
  12. http://pastebin.com/SX5R69vY
  13.  
  14. they all have the same server setup as shown below
  15.  
  16. PORT STATE SERVICE VERSION
  17. 22/tcp open ssh OpenSSH 5.5p1 Debian 6+squeeze4 (protocol 2.0)
  18. 80/tcp open http nginx web server 0.7.67
  19. 445/tcp filtered microsoft-ds
  20. Service Info: OS: Linux
  21.  
  22. Based on previous similar studied patterns discussed in
  23. http://labs.umbrella.com/2014/02/14/when-ips-go-nuclear/
  24.  
  25. we predict Nuclear will ride in the next days on the remaining IPs of this range 198.50.143.64 - 198.50.143.79
  26.  
  27. Furthermore, the current Nuclear subdomains are using
  28.  
  29. dns1.pirozhkoff.ru and dns2.pirozhkoff.ru as nameservers
  30.  
  31. dns1.pirozhkoff.ru is hosted on 198.50.212.139
  32. which is part of the OVH sub-allocated range 198.50.212.136 - 198.50.212.143
  33.  
  34. reserved by the bad actor "Penziatki". This actor has been covered before for example in http://blog.dynamoo.com/search/label/R5X.org
  35.  
  36. The same actor reserved these ranges
  37.  
  38. 198.50.212.128 - 198.50.212.131
  39. 198.50.212.132 - 198.50.212.135
  40. 198.50.212.136 - 198.50.212.143
  41.  
  42. dns2.pirozhkoff.ru is hosted on 198.50.230.198
  43. which is part of 198.50.230.196 - 198.50.230.199
  44.  
  45. The suspicious actor behind reserving that OVH range is also behind these ranges discussed in
  46. http://labs.umbrella.com/2014/02/14/when-ips-go-nuclear/
  47.  
  48. 198.50.230.192 - 198.50.230.195
  49. 198.50.230.196 - 198.50.230.199
  50. 198.50.230.200 - 198.50.230.203
  51. 198.50.230.204 - 198.50.230.207
  52. 198.50.230.208 - 198.50.230.215
  53. 198.50.230.216 - 198.50.230.223
  54.  
  55. Block/monitor these ranges
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement